Elastic Packetbeat
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*
- ~7
- ~8.0.0, <= 8.19.8
- ~9.0.0, <= 9.1.8
- ~9.2.0, <= 9.2.2
A buffer overflow vulnerability has been identified in Elastic Packetbeat versions 7.x, 8.x (8.0.0 through 8.19.8), and 9.x (9.0.0 through 9.1.8 and 9.2.0 through 9.2.2). This vulnerability arises from an out-of-bounds read in the NFS protocol dissector, allowing an unauthenticated remote attacker to perform a buffer overflow. Exploitation of this vulnerability leads to a denial-of-service condition, causing a reliable process crash when Packetbeat handles truncated XDR-encoded RPC messages via the NFS protocol.
Exploitation of this vulnerability causes a process crash, leading to a denial-of-service condition.
Users can upgrade to Packetbeat versions 8.19.9, 9.1.9, or 9.2.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.